Privacy Policy
Last updated August 5, 2026
GERDMenu helps users scan restaurant menus and compare dishes against their selected reflux trigger profile. GERDMenu is informational only and is not medical advice, diagnosis, or treatment.
Information processed
- Your trigger settings and scan history are stored locally on your device.
- Before the first real scan, the app asks for permission to send a compressed menu photo, optional OCR checklist text, a pseudonymous device identifier, selected trigger and tolerance settings, and recent meal follow-up context to the GERDMenu backend for reflux-risk guidance. You can withdraw this permission in Profile → Data & Privacy; the next real scan will ask again.
- The GERDMenu backend is hosted on Cloudflare. It sends the menu photo, OCR text, and selected profile context to OpenAI for GPT-5.4 structured menu analysis, then applies deterministic GERD guardrails before returning results.
- The GERDMenu backend does not intentionally store the original menu photo. It is forwarded for analysis; parsed menu results may be cached as described below.
- A pseudonymous device identifier is stored in your iCloud Keychain so limits and purchase access can remain consistent across reinstalls, and is used for scan limits, entitlement verification, cache matching, and abuse prevention.
- Apple-signed transaction information and the pseudonymous device identifier are sent to the backend to verify Premium access and restore purchases. Plan, product, expiration, and trial status are also mirrored in your private iCloud/CloudKit database for continuity across your Apple devices.
Analytics
- Analytics is optional and disabled until you choose Allow Analytics. If allowed, GERDMenu sends product-usage events to our analytics provider, PostHog, keyed to the same pseudonymous device identifier (no account, email, or name).
- These events include screens viewed, onboarding selections (such as your goal, age range, how long you have had GERD/gastritis, how you heard about us, and which default cautions you relax), and subscription/paywall actions.
- The name you optionally enter during onboarding is stored only on your device and is never sent to analytics.
- This is product analytics only: GERDMenu does not use advertising tracking, does not track you across other companies' apps or websites, and does not sell your data.
- You can stop new analytics collection at any time in Profile → Data & Privacy without losing app features.
Service providers and safeguards
GERDMenu uses Cloudflare to host the backend and cache, OpenAI to analyze menus, and PostHog for optional analytics. We use these providers only under service terms that require them to protect data and limit processing to authorized purposes. GERDMenu requires the same or equivalent protection described in this policy and remains responsible for data they process on our behalf.
Information not collected
- No account, email address, name, or login is required.
- Menu scans are not used to identify you.
Storage and retention
Parsed menu results may be cached by the Cloudflare-hosted backend for up to 7 days to reduce repeated processing. Cache keys may reflect menu content, the pseudonymous device identifier, and selected profile context. Daily abuse records expire shortly after the applicable day, monthly counters expire after the applicable month, verified backend entitlement records expire after the subscription and grace period, and a pseudonymous lifetime flag is retained to enforce the one-time free scan.
GERDMenu requests OpenAI processing without persistent response storage. Under OpenAI's standard API controls, request content and related abuse-monitoring logs may nevertheless be retained for up to 30 days, or longer when legally required; API content is not used to train OpenAI models unless the API account owner separately opts in.
If analytics is allowed, PostHog analytics events remain in GERDMenu's PostHog project until deleted under the project's retention and deletion controls or in response to a supported deletion request. Turning analytics off stops new events but does not automatically erase events already collected. You may request deletion of associated analytics by emailing us.
Your local scan history remains on your device unless you delete the app. The pseudonymous identifier remains in iCloud Keychain, and the private CloudKit subscription record remains in your iCloud account, until removed through your Apple account/device storage controls or a supported data request.
Contact
For privacy questions or data requests, email casstao@gmail.com. For general help, visit GERDMenu Support.